CVE-2022-41316
Summary
| CVE | CVE-2022-41316 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-10-12 21:15:00 UTC |
| Updated | 2022-12-03 15:02:00 UTC |
| Description | HashiCorp Vault and Vault Enterprise’s TLS certificate auth method did not initially load the optionally configured CRL issued by the role's CA into memory on startup, resulting in the revocation list not being checked if the CRL has not yet been retrieved. Fixed in 1.12.0, 1.11.4, 1.10.7, and 1.9.10. |
Risk And Classification
Problem Types: CWE-295
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| HCSEC-2022-24 - Vault's TLS Cert Auth Method Only Loaded CRL After First Request - Security - HashiCorp Discuss | MISC | discuss.hashicorp.com | |
| CVE-2022-41316 HashiCorp Vault Vulnerability in NetApp Products | NetApp Product Security | CONFIRM | security.netapp.com | |
| HashiCorp Discuss | MISC | discuss.hashicorp.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.